Security leadership, from strategy to delivery
I lead the cybersecurity practice at Aurionpro Solutions Limited — running VAPT, Red Team, SOC, GRC and Security Solutioning teams end-to-end, with ownership of delivery, presales, OEM partnerships and practice P&L.
I design and deliver enterprise security programmes for banks, insurers, market infrastructure institutions, power utilities, smart cities and government bodies — covering security architecture, offensive security, SOC build and operations, and regulatory compliance under RBI, SEBI CSCRF, IRDAI, PCI DSS, ISO 27001 and the DPDP Act. I also own the OEM partner ecosystem across 20+ security vendors, running evaluations, demonstrations and proofs of concept so that every solution is matched to the client's risk posture and regulatory mandate.
More recently I have built out an AI security service line — AI-augmented VAPT, LLM and GenAI application testing, and AI governance aligned to NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10 and MITRE ATLAS — and contribute as part of the team within the CERT-In AI Cyber War Room, working on AI Security Blueprint drafting and governance.
Enterprise & Government Clients
Years in Cybersecurity
Practice Teams Led
Professional Certifications
Experience, education and credentials
Cybersecurity leader with 6 years of experience across security practice management, security architecture, governance and offensive security. Currently leading the cybersecurity practice at Aurionpro Solutions Limited, serving 20+ enterprise and government customers across BFSI, insurance, stock exchange, power utilities, smart city and public sector.
Indian Institute of Technology (IIT) Patna
Advanced study in cloud architecture, distributed systems and secure infrastructure design.
Yashwantrao Chavan College of Engineering (YCCE), Nagpur
Final year project: YCCE Buddy, an autonomous hospitality assistant replacing a traditional reception desk.
Aurionpro Solutions Limited, India
Aurionpro Solutions Limited, India
Ministry of Social Justice & Empowerment, Government of India — deputed through Aurionpro
All India Council for Technical Education (AICTE), Ministry of Education, GoI
Security capabilities I lead and deliver
Web, mobile, API, network, infrastructure and cloud VAPT; red and purple teaming; source code review (SAST) and DAST; OT / ICS / SCADA testing; breach and attack simulation; hardening review and Safe-to-Host certification.
GenAI and LLM application security testing; prompt injection, jailbreak and data-poisoning assessment; AI red teaming and model-evasion testing; model risk, bias and robustness review; AIBOM and AI supply-chain security aligned to NIST AI RMF, ISO/IEC 42001 and the EU AI Act.
Hypothesis-driven, ATT&CK-mapped threat hunting; cyber threat intelligence and attack-surface management; APT defence, deception and honeypots; incident response, digital forensics and malware analysis; compromise assessment and CERT-In reporting.
ISO 27001 / 22301 / 20000-1 / 42001, NIST CSF, CIS Controls, PCI DSS and SOC 1/2 implementation; internal, external and third-party audit; gap and maturity assessment; risk assessment and treatment; policy development; vendor risk (TPRM) and GRC tooling.
RBI, SEBI CSCRF, IRDAI and MAS alignment; system and cyber audit for regulated entities; SAR audit; DPDP Act 2023 readiness; AUA / KUA compliance; dark pattern audit; DPO-as-a-Service; CERT-In empanelled audit support.
Zero Trust and ZTNA; IAM, IGA, PAM, MFA and NAC; next-generation SIEM, SOAR, UEBA and XDR; DLP, DAM, encryption and PKI; email security, WAF, CASB, CSPM, CWPP and container / Kubernetes security.
Virtual CISO engagements: security strategy, roadmap and programme build; security architecture advisory; board and executive risk reporting; tool rationalisation and budget optimisation; M&A due diligence; awareness programmes and cyber-insurance readiness.
SOC-as-a-Service with 24×7 monitoring and response; MDR and co-managed or fully managed SIEM; threat hunting, log management and analytics; managed VAPT and vulnerability management; managed PAM / IAM; device and patch management; dark-web monitoring.
RFP and tender solutioning for government and BFSI procurement; technical solution documents, compliance matrices, bill of materials and costing; OEM evaluation, product demonstrations and proofs of concept; bid defence and evaluation-committee presentations.
Selected engagements — client names withheld under NDA
Open to conversations on security leadership, architecture and advisory
Nagpur, Maharashtra, India
Available for engagements across India and the GCC
+91 95612 15406